Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 88% confidence
- Finding
- The skill clearly instructs the agent to perform network access and shell execution, yet it declares no permissions. This undermines the permission model and can cause users or orchestrators to approve a skill without understanding that it will log in to a remote service, execute local commands, and manipulate files.
